9.8

CVE-2023-38029

Saho’s attendance devices ADM100 and ADM-100FP has insufficient filtering for special characters and file type within their file uploading function. A unauthenticate remote attacker authenticated can upload and execute arbitrary files to perform arbitrary system commands or disrupt service.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SahoAdm-100 Firmware Version0.0.4.0
   SahoAdm-100 Version-
SahoAdm-100 Firmware Version0.0.4.3
   SahoAdm-100 Version-
SahoAdm-100 Firmware Version0.0.4.6
   SahoAdm-100 Version-
SahoAdm-100 Firmware Version0.0.4.8
   SahoAdm-100 Version-
SahoAdm-100 Firmware Versionq20100602
   SahoAdm-100 Version-
SahoAdm-100 Firmware Versiont190
   SahoAdm-100 Version-
SahoAdm-100 Firmware Versiont17041702
   SahoAdm-100 Version-
SahoAdm-100 Firmware Versiont18051803
   SahoAdm-100 Version-
SahoAdm-100fp Firmware Versionq20100602
   SahoAdm-100fp Version-
SahoAdm-100fp Firmware Versiont190
   SahoAdm-100fp Version-
SahoAdm-100fp Firmware Versiont17041702
   SahoAdm-100fp Version-
SahoAdm-100fp Firmware Versiont18051803
   SahoAdm-100fp Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.544
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
twcert@cert.org.tw 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.